Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networks.
The research, titled “Zero Day Provisioning,” was presented at Black Hat USA 2026 and focuses on weaknesses in the trust relationships that enable Omada controllers to automatically configure gateways, routers, switches, and wireless access points.
TP-Link has issued advisories for multiple CVEs, while four findings were addressed outside the CVE process.
ZTP is designed to simplify large-scale deployments by allowing newly connected devices to identify their controller, authenticate, receive configuration data, and accept firmware or policy changes without requiring hands-on administration.
However, Forescout identified flaws in Omada’s onboarding and communication processes, including client-side code execution vulnerabilities, sensitive information disclosure, device spoofing, hijacking, and the compromise of encrypted communications.
The impact is not limited to Omada controllers and infrastructure devices; it also affects certain Festa products, VIGI surveillance platforms, TP-Link cloud services, and Android applications, including Tapo, Kasa, Omada, and Tether.
Several defects undermine the cryptographic chain of trust. CVE-2025-15627 involves a hard-coded private key in version 1 of the Omada protocol, while CVE-2025-15628 pertains to a hard-coded TLS certificate and its associated private key in version 2.
CVE-2025-15629 arises from a predictable RC4 encryption key, and CVE-2025-9291 highlights insufficient Common Name validation when devices verify controller certificates.
Collectively, these weaknesses could allow a knowledgeable adversary to impersonate trusted components or intercept supposedly secure traffic.
The most critical attack path begins before a device is fully enrolled. Researchers noted that threat actors could enumerate predictable serial numbers, retrieve related device information, and identify systems awaiting cloud adoption.
By spoofing a target device’s MAC address and exploiting a cloud-adoption race condition tracked as CVE-2025-15630, an attacker could obtain provisioning material meant for legitimate devices. Vulnerabilities related to default adoption credentials and insecure credential handling could further expose site credentials, administrator hashes, and potentially VPN secrets.
Forescout also identified CVE-2025-9289, a cross-channel scripting issue in Omada controller interfaces, and CVE-2025-9292, which involves an overly permissive web security policy under specific conditions.
An attacker who gains access could inject malicious JavaScript, trick an administrator into entering credentials, and use the stolen access to modify managed infrastructure.
Combined with previously disclosed TP-Link command-injection vulnerabilities, CVE-2025-7850 and CVE-2025-7851, these flaws could lead to a pathway from external device discovery to internal network access.
| CVE / Finding | Vulnerability |
|---|---|
| CVE-2025-9289 | Cross-channel scripting in Omada controller web interface |
| CVE-2025-9290 | Non-unique or empty salts enable static credential hashes |
| CVE-2025-9291 | Insufficient certificate Common Name validation |
| CVE-2025-9292 | Permissive CSP enables cross-origin access-control bypass |
| CVE-2025-9293 | Insufficient certificate validation in TP-Link Android apps |
| CVE-2025-15544 | Weak protection of site credentials during device adoption |
| CVE-2025-15627 | Hard-coded private key in Omada protocol version 1 |
| CVE-2025-15628 | Hard-coded TLS certificate and private key in protocol version 2 |
| CVE-2025-15629 | Predictable / low-entropy RC4 key in protocol version 1 |
| CVE-2025-15630 | Cloud device-adoption race condition |
| CVE-2025-15631 | Unsalted MD5 device-management password hashes protected with a hard-coded key |
| FSCT-2025-0003 | Unadopted devices can be adopted using serial numbers |
| FSCT-2025-0008 | Adoption challenges signed using default credentials |
| FSCT-2025-0011 | Predictable sequential serial numbers expose device information |
| FSCT-2025-0014 | Arbitrary-file upload and retrieval via unauthenticated temporary links |
Organizations using Omada are advised to update affected device firmware, controller software, and mobile applications according to TP-Link’s advisories.
Administrators should also replace shared provisioning passwords with strong, unique credentials, enable multifactor authentication for TP-Link cloud accounts where available, rotate possibly exposed VPN keys and certificates, and ensure controllers are not directly exposed to the internet.
Implementing network segmentation, 802.1X with Network Access Control (NAC), port security, dynamic ARP inspection, wireless client isolation, and monitoring for anomalous adoption or controller activity can help reduce the impact of a successful attack.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…